Impact
Crater Invoice through version 6.0.6 suffers from a path‑traversal flaw in its self‑update API. Authenticated company owners can submit a crafted ZIP file containing '../' sequences to the unzip endpoint. The vendor’s implementation passes the ZIP entry names directly to PHP's ZipArchive::extractTo() without sanitization, allowing arbitrary files to be written outside the intended extraction directory. An attacker can place a PHP file in the web‑accessible public folder and gain remote code execution on the server.
Affected Systems
Crater Invoice Inc. software, product Crater, version 6.0.6 is affected. Systems deploying this release and allowing authenticated company owners to use the self‑update feature are vulnerable. No other versions or products are listed as affected.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. EPSS is not available, so the current exploitation likelihood is unclear; however, the flaw is accessible only to authenticated owners, reducing the initial attack surface. Because the flaw permits arbitrary PHP files in a public web directory, successful exploitation leads to full control of the affected server. The vulnerability is not listed in CISA KEV, but its remote code execution potential warrants immediate attention.
OpenCVE Enrichment